If your business runs a Check Point Spark or Security Gateway firewall, patch it today. The Cybersecurity and Infrastructure Security Agency (CISA) added the Check Point firewall vulnerability tracked as CVE-2026-85102 to its Known Exploited Vulnerabilities catalog on September 22, 2026, after Check Point confirmed attackers were already exploiting it against Spark customers. Both this flaw and a related one, CVE-2026-93616, carry the maximum severity score and give an attacker who has no login at all a path to run code on the device.
- CVE-2026-85102 hits Check Point Security Gateway and Spark Firewall (both centrally and locally managed) through a broken certificate check during VPN negotiation, letting an unauthenticated attacker execute code.
- CVE-2026-93616 is a pre-authentication path traversal bug in Check Point Security Management, under limited exploitation since July 23, 2026, according to Check Point.
- Check Point shipped a fix for CVE-2026-85102 on September 9, 2026, but real attacks against Spark customers began just three days later, on September 12.
- CISA’s directive gives federal agencies until September 25, 2026 to patch systems on this list. Southwest Florida businesses should treat that same date as their own deadline.
- Spark Firewall is marketed specifically to small and midsize offices, the exact segment a lot of Naples, Fort Myers, and Tampa businesses run their network on.
What exactly is CVE-2026-85102?
Check Point’s own security advisory describes it as improper validation of certificate data during VPN negotiation. In plain terms, when a device tries to establish a VPN connection to the firewall, the firewall is supposed to check that the certificate presented is legitimate before trusting it. This flaw lets an attacker hand over a malformed certificate that the gateway processes anyway, corrupting memory in a way that can lead to arbitrary code execution. No username, password, or prior access is needed.
Is my business actually at risk?
If you have a Check Point Security Gateway or Spark Firewall sitting at your network edge and it has not been patched since September 9, 2026, yes. Check Point’s advisory names Spark Firewall directly, both the centrally managed version larger IT providers roll out across multiple sites and the locally managed version a smaller office might run on its own. The firewall and VPN appliance is usually the one device with a foot in both your internal network and the open internet, so a flaw here is not a minor inconvenience. It is a direct path from the outside world into whatever sits behind it: file servers, point-of-sale systems, accounting software, patient or client records.
How do I know if my firewall was already hit?
Check Point’s guidance is to review logs for anomalous certificate-based Mobile Access logins and to watch for unusual internal port and service scanning, the kind of activity that shows up after an attacker has already gotten a foothold and is mapping out what else is on the network. If you do not have someone reviewing firewall logs regularly, this is a good moment to change that. A firewall that is only ever configured and forgotten is a firewall nobody is watching when something like this happens.
What should I do right now?
Confirm what firewall brand and model your business actually runs. A surprising number of small businesses cannot answer that question quickly, which is one more reason a basic IT asset inventory pays for itself the first time an advisory like this one lands. If you do run Check Point gear, get the patch installed from the support portal immediately, don’t wait for a routine maintenance window. This is the second network-edge device vulnerability we have flagged for Southwest Florida businesses this year; see our earlier post on a router security warning for the same underlying lesson: the boxes at your network perimeter need the same patching discipline as your laptops and servers, and usually get less of it.
Frequently asked questions
What is the Check Point firewall vulnerability everyone is talking about?
It is CVE-2026-85102, a certificate validation flaw in Check Point Security Gateway and Spark Firewall that lets an attacker with no login credentials run code on the device during VPN negotiation. A second bug, CVE-2026-93616, affects Check Point Security Management. Both are rated 9.8 out of 10 in severity and both are on CISA’s Known Exploited Vulnerabilities list.
Does this affect small business firewalls or just big enterprise gear?
Spark Firewall is Check Point’s line built for small and midsize offices, and it is named directly in the advisory. If your IT provider put a Check Point box at your edge, whether it is a large enterprise gateway or a small Spark unit, you are in scope.
How do I know if my business actually uses a Check Point firewall?
Ask your IT provider or internal IT staff which brand and model sits at your network edge. If you manage it yourself, log into the appliance’s admin console, the vendor name is usually on the login screen and on a label on the hardware itself.
What if I think I’ve already been hit?
Stop patching guesswork and get help. Pull firewall and VPN logs for anomalous certificate-based logins and unusual internal port scanning going back to September 12, 2026, and have someone who does incident response review them before you assume the device is clean.
SWFIT offers a free 15-minute review of your firewall and network edge for Southwest Florida businesses who want a second set of eyes on this. Reach out through our contact page to get on the calendar.